Ingénieur cybersécurité renforçant la posture de sécurité d’EDC, société canadienne de financement du commerce international. Intégration de contrôles, DevSecOps et sécurité de l’IA.
Responsibilities
Collaborate with the infrastructure, cloud, and application teams to integrate security controls into EDC’s technology stack
Identify security gaps and vulnerabilities, prioritize remediation measures, and develop tactical plans
Design and implement security and automation tools and hardening standards
Contribute to threat modeling, security architecture reviews, and assessments of emerging technologies
Monitor the threat landscape and develop actionable improvements
Act as a security partner to agile and delivery teams throughout design, development, and deployment
Conduct security reviews of project documentation, architecture diagrams, code changes, and configuration decisions
Promote secure-by-default practices, DevSecOps, and a shift-left approach
Design and maintain reusable security standards, guidelines, and templates
Advise engineering and product stakeholders and translate security risks into business language
Assess security risks associated with AI and machine learning workloads
Support EDC’s AI security approach through risk assessments, security reviews, and governance feedback
Use AI and machine learning to improve security operations, including anomaly detection, threat hunting, and alert triage
Explore and evaluate AI-assisted security tools
Collaborate with stakeholders to align security practices with EDC’s strategic objectives and 2030 roadmap
Communicate complex security concepts to technical and non-technical audiences
Contribute to key performance indicators and metrics tracking the progress of the security posture
Contribute to continuous improvement initiatives and the evolution of the security program
Requirements
Postsecondary degree in computer science, information security, engineering, or a related field, combined with equivalent practical experience
At least 7 years of hands-on experience in cybersecurity engineering, application or cloud security, or a similar technical role
Extensive, demonstrated experience across multiple security domains, such as application, cloud, network, or endpoint security, identity, data protection, or vulnerability management
Expertise in several areas of security and working knowledge of others
Experience integrating security into software development life cycle processes, continuous integration and continuous delivery practices, and agile workflows
Strong cloud security expertise, preferably with Azure; experience with AWS and GCP is also recognized
Hands-on experience with a broad range of security tools, including SIEM, vulnerability management, SAST, DAST, secrets management, identity platforms, endpoint security, and cloud security tools
Knowledge of AI and machine learning security considerations
Experience with AI security, including hands-on work, architecture reviews, governance, risk assessment, proof-of-concept development, or collaboration with AI platform teams
Excellent communication skills and the ability to translate security risks into business language
Collaborative, curious, comfortable with ambiguity, and able to work independently
CISSP, CCSP, CEH, OSCP, Azure Security specialization, Microsoft professional certifications, or equivalent certifications are considered an asset
Experience with AI and machine learning platforms, large language models, or analytics and data science pipelines is considered an asset
Experience with Copilot Studio, Databricks, AI embedded in SaaS, or similar AI services is considered an asset
Knowledge of Salesforce, ServiceNow, and other SaaS security models is considered an asset
Knowledge of Canadian compliance and regulatory frameworks applicable to federal Crown corporations is considered an asset
Experience writing scripts and coding with Python, PowerShell, or Bash is considered an asset
Fluency in both official languages, English and French, is considered an asset
Preference will be given to candidates legally authorized to work in Canada at the time of application
Candidates must meet government security requirements
Benefits
Performance-based compensation
Various hybrid work options
Three to four weeks of vacation
Holiday closure period
Shorter summer Fridays
Meeting-free Fridays
Ongoing learning opportunities, training programs, and workshops
Language training
Diverse and inclusive workplace
Wellness initiatives
Mental health support
Fitness programs
Volunteer activities and social responsibility programs
Relocation assistance available to eligible candidates
Security architect securing Thomson Reuters’ legal, tax, compliance, government, and media technology platforms. Leading architecture reviews, cloud security, threat modelling, and AI system risk controls.
Product Security Engineer securing Cohere’s enterprise AI products and foundation models. Reviewing architecture, threat modeling capabilities, and testing vulnerabilities across production systems.
Senior Program Manager driving enterprise cybersecurity programs for NBCUniversal, a global media and entertainment company. Coordinating technical delivery, operational change, adoption, risk, and executive reporting.
Head of Information Security leading OpenZeppelin’s enterprise security, privacy, IT, and AI governance programs. Securing open - source infrastructure used across onchain finance and digital assets.
Red Team Security Engineer evaluating Motive's fleet - management platform and cloud environments. Executing adversary simulations, validating detection coverage, and driving remediation of security issues.
Information Systems Security Manager securing RideCo’s cloud - based on - demand transit platform. Leading compliance, risk management, incident response, and security operations.